Skip to main content

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

Bulletin ID: 2026-120-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/01/2026 08:30 AM PDT

Description:

The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSON map causes the mount utility to parse them as separate mount options.

Impacted versions: >= v3.1.0 AND <= v3.4.2

Resolution:

This issue has been addressed in Amazon EFS CSI Driver version v3.5.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values.

References:


Please email aws-security@amazon.com with any security questions or concerns..